Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
Ransomware Group Rapidly Disables Security and Encrypts Networks

Ransomware Group Rapidly Disables Security and Encrypts Networks

Posted on September 3, 2026 By CWS

The Gentlemen ransomware group has been observed executing full network encryption with alarming speed, disabling critical security measures within a 24-hour timeframe. The group employs a ransomware-as-a-service model, allowing affiliates to attack accessible targets. Their method includes a double-extortion technique, where data is first stolen and then encrypted, creating both operational and privacy threats for victims.

Understanding the Ransomware Tactics

Research by Sophos on 15 incidents attributed to this group, also known as GOLD SHERWOOD, reveals a repetitive strategy. The group often gains initial access through exposed firewall management interfaces, unpatched systems, or stolen VPN credentials. A particular vulnerability in Fortinet SSL VPNs, when not secured with multi-factor authentication, provides a gateway for these attackers, highlighting the need for robust infrastructure security.

Once inside the network, the attackers utilize legitimate domain credentials and Remote Desktop Protocol to navigate systems. They strategically place their toolkit in trusted Windows locations to avoid detection, mapping data stores and backup systems before launching the ransomware attack. Administrative controls are manipulated, including changing passwords and enabling remote access, often by creating new firewall rules to maintain access even if the initial VPN session is lost.

Disabling Security Measures

The Gentlemen group meticulously removes barriers to encryption by employing both custom and publicly available tools to disable antivirus and endpoint detection systems. They weaken Windows Defender by altering settings and adding scan exclusions, following a broader trend among ransomware operators to neutralize security and backup software before spreading across a network.

In addition to disabling security, they target backup services, often just before initiating encryption, to hinder recovery efforts. In some cases, they erase event logs, further complicating incident response efforts. These actions underscore the importance of maintaining independent backup controls and regularly testing recovery plans to mitigate the impact of such attacks.

Implications and Preventive Measures

The rapid progression from network access to ransomware deployment underscores the crucial need for timely detection and prevention measures. Organizations should prioritize patching internet-facing firewalls and VPN appliances, enforcing multi-factor authentication for remote access, and restricting RDP exposure. Monitoring for unusual activity and reviewing new privileged accounts can aid in early detection of potential threats.

Sophos’ report emphasizes the importance of alerting on atypical activities, such as the use of unfamiliar data-transfer utilities and the modification of Windows Defender settings. By maintaining vigilance and updating security protocols, organizations can reduce the risk of falling victim to such swift and damaging ransomware attacks.

In conclusion, the evolving tactics of ransomware groups like The Gentlemen highlight the ongoing challenges in securing network infrastructures. As cyber threats continue to advance, staying informed and implementing comprehensive security measures is essential for protecting valuable data and maintaining operational continuity.

Cyber Security News Tags:Backup, cyber attack, Cybersecurity, data breach, EDR, Encryption, Fortinet, IT security, Malware, network encryption, network security, Phishing, Ransomware, Sophos, VPN

Post navigation

Previous Post: Pegasus Zero-Click Spyware Targeted Serbian Activists
Next Post: Massive Driver License Data Breach on Dark Web

Related Posts

Windows Servers Face RDS Issues After September Updates Windows Servers Face RDS Issues After September Updates Cyber Security News
Unremovable Spyware on Samsung Devices Comes Pre-installed on Galaxy Series Devices Unremovable Spyware on Samsung Devices Comes Pre-installed on Galaxy Series Devices Cyber Security News
SerpApi Challenges SearchApi Over Technology Misuse SerpApi Challenges SearchApi Over Technology Misuse Cyber Security News
Ghostjacking Threat: AI Coding Agents at Risk Ghostjacking Threat: AI Coding Agents at Risk Cyber Security News
CVE-2026-39987 Exploited to Deploy Blockchain Backdoor CVE-2026-39987 Exploited to Deploy Blockchain Backdoor Cyber Security News
Threat Actors Using AI Generated Malicious Job Offers to Deploy PureRAT Threat Actors Using AI Generated Malicious Job Offers to Deploy PureRAT Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • CenterPoint Energy Reports Customer Data Breach Incident
  • Hackuity Secures $19M to Boost AI Vulnerability Management
  • Browser Extension Risks AI Assistant Security
  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • CenterPoint Energy Reports Customer Data Breach Incident
  • Hackuity Secures $19M to Boost AI Vulnerability Management
  • Browser Extension Risks AI Assistant Security
  • Urgent Patch for Major Check Point Vulnerability Released
  • Google Fixes Pixel Zero-Day Vulnerability Amid Attacks

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark